Skip to main content

Vendor/product archive

totolink / ex200_firmware CVEs

Beta · best-effort

19 CVEs tagged to totolink / ex200_firmware4 Critical, 9 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2024-53333

Published Nov 21, 2024

TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary co…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7336

Published Aug 1, 2024

A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7335

Published Aug 1, 2024

A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31807

Published Apr 8, 2024

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-31806

Published Apr 8, 2024

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorizat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43711

Published Jan 4, 2022

The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be construct…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1